如何在XDR高级狩猎中提取Threat Intelligence Verdict?
Defender XDR高级狩猎:EmailUrlInfo表恶意URL查询方案
可行方案说明
你提到的Threat Intelligence Verdict字段确实不在EmailUrlInfo主表中,但可以通过KQL关联其他内置表获取该数据,也能直接筛选出Defender判定为恶意的URL,具体实现如下:
1. 关联UrlClickEvents表获取威胁判定
UrlClickEvents表存储了URL的威胁情报判定结果,可通过Url字段与EmailUrlInfo表关联,提取目标字段:
EmailUrlInfo | join kind=inner ( UrlClickEvents | where isnotempty(ThreatIntelligenceVerdict) | project Url, ThreatIntelligenceVerdict ) on Url | where ThreatIntelligenceVerdict == "Malicious" | project Timestamp, SenderFromAddress, RecipientEmailAddress, Url, ThreatIntelligenceVerdict
2. 直接筛选恶意URL的简化写法
若仅需聚焦恶意URL,也可从UrlClickEvents表出发反向关联EmailUrlInfo:
UrlClickEvents | where ThreatIntelligenceVerdict == "Malicious" | join kind=inner EmailUrlInfo on Url | project Timestamp, SenderFromAddress, RecipientEmailAddress, Url, ThreatIntelligenceVerdict
3. 补充:关联UrlEntity表覆盖更多场景
如果部分URL无点击事件记录,可尝试关联UrlEntity表(通过Properties字段提取判定信息):
EmailUrlInfo | join kind=leftouter ( UrlEntity | project Url, ThreatIntelligenceVerdict = Properties.ThreatIntelligenceVerdict ) on Url | where ThreatIntelligenceVerdict in ("Malicious", "Suspicious") | project Timestamp, SenderFromAddress, RecipientEmailAddress, Url, ThreatIntelligenceVerdict
字段取值说明
ThreatIntelligenceVerdict的常见有效值包括:Malicious、Suspicious、Clean、Unknown,可根据需求调整筛选条件。
内容的提问来源于stack exchange,提问作者Katie
相关产品推荐
相关产品推荐

